{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T16:10:05Z","timestamp":1778947805083,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":46,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,10,10]],"date-time":"2022-10-10T00:00:00Z","timestamp":1665360000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Defense Acquisition Program Administration(DAPA) and Agency for Defense Development(ADD)","award":["UD190031RD"],"award-info":[{"award-number":["UD190031RD"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,10,10]]},"DOI":"10.1145\/3503161.3548362","type":"proceedings-article","created":{"date-parts":[[2022,10,10]],"date-time":"2022-10-10T15:43:01Z","timestamp":1665416581000},"page":"1905-1913","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":19,"title":["Defending Physical Adversarial Attack on Object Detection via Adversarial Patch-Feature Energy"],"prefix":"10.1145","author":[{"given":"Taeheon","family":"Kim","sequence":"first","affiliation":[{"name":"Korea Advanced Institute of Science &amp; Technology, Daejeon, Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Youngjoon","family":"Yu","sequence":"additional","affiliation":[{"name":"Korea Advanced Institute of Science &amp; Technology, Daejeon, Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yong Man","family":"Ro","sequence":"additional","affiliation":[{"name":"Korea Advanced Institute of Science &amp; Technology, Daejeon, Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,10,10]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases. Springer, 52--68","author":"Chen Shang-Tse","year":"2018","unstructured":"Shang-Tse Chen , Cory Cornelius , Jason Martin , and Duen Horng Polo Chau . 2018 . Shapeshifter: Robust physical adversarial attack on faster rcnn object detector . In Joint European Conference on Machine Learning and Knowledge Discovery in Databases. Springer, 52--68 . Shang-Tse Chen, Cory Cornelius, Jason Martin, and Duen Horng Polo Chau. 2018. Shapeshifter: Robust physical adversarial attack on faster rcnn object detector. In Joint European Conference on Machine Learning and Knowledge Discovery in Databases. Springer, 52--68."},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.236"},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.691"},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475338"},{"key":"e_1_3_2_2_5_1","volume-title":"Histograms of oriented gradients for human detection. In 2005 IEEE computer society conference on computer vision and pattern recognition (CVPR'05)","author":"Dalal Navneet","unstructured":"Navneet Dalal and Bill Triggs . 2005. Histograms of oriented gradients for human detection. In 2005 IEEE computer society conference on computer vision and pattern recognition (CVPR'05) , Vol. 1 . Ieee , 886--893. Navneet Dalal and Bill Triggs. 2005. Histograms of oriented gradients for human detection. In 2005 IEEE computer society conference on computer vision and pattern recognition (CVPR'05), Vol. 1. Ieee, 886--893."},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.5555\/2354409.2354978"},{"key":"e_1_3_2_2_7_1","volume-title":"Proceedings of the Asian Conference on Computer Vision.","author":"Gittings Thomas","year":"2020","unstructured":"Thomas Gittings , Steve Schneider , and John Collomosse . 2020 . Vaxa-Net: Training-time Defence Against Adversarial Patch Attacks . In Proceedings of the Asian Conference on Computer Vision. Thomas Gittings, Steve Schneider, and John Collomosse. 2020. Vaxa-Net: Training-time Defence Against Adversarial Patch Attacks. In Proceedings of the Asian Conference on Computer Vision."},{"key":"e_1_3_2_2_8_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow , Jonathon Shlens , and Christian Szegedy . 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 ( 2014 ). Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2018.00210"},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00775"},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00080"},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01076"},{"key":"e_1_3_2_2_13_1","volume-title":"International Conference on Machine Learning. PMLR, 2507--2515","author":"Karmon Danny","year":"2018","unstructured":"Danny Karmon , Daniel Zoran , and Yoav Goldberg . 2018 . Lavan: Localized and visible adversarial noise . In International Conference on Machine Learning. PMLR, 2507--2515 . Danny Karmon, Daniel Zoran, and Yoav Goldberg. 2018. Lavan: Localized and visible adversarial noise. In International Conference on Machine Learning. PMLR, 2507--2515."},{"key":"e_1_3_2_2_14_1","volume-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision. 3050--3059","author":"Kim Jung Uk","year":"2021","unstructured":"Jung Uk Kim , Sungjune Park , and Yong Man Ro . 2021 . Robust smallscale pedestrian detection with cued recall via memory learning . In Proceedings of the IEEE\/CVF International Conference on Computer Vision. 3050--3059 . Jung Uk Kim, Sungjune Park, and Yong Man Ro. 2021. Robust smallscale pedestrian detection with cued recall via memory learning. In Proceedings of the IEEE\/CVF International Conference on Computer Vision. 3050--3059."},{"key":"e_1_3_2_2_15_1","volume-title":"Towards Versatile Pedestrian Detector with Multisensory-Matching and Multispectral Recalling Memory. In 36th AAAI Conference on Artificial Intelligence (AAAI 22)","author":"Kim Jung Uk","year":"2022","unstructured":"Jung Uk Kim , Sungjune Park , and Yong Man Ro . 2022 . Towards Versatile Pedestrian Detector with Multisensory-Matching and Multispectral Recalling Memory. In 36th AAAI Conference on Artificial Intelligence (AAAI 22) . Association for the Advancement of Artificial Intelligence. Jung Uk Kim, Sungjune Park, and Yong Man Ro. 2022. Towards Versatile Pedestrian Detector with Multisensory-Matching and Multispectral Recalling Memory. In 36th AAAI Conference on Artificial Intelligence (AAAI 22). Association for the Advancement of Artificial Intelligence."},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP43922.2022.9747896"},{"key":"e_1_3_2_2_17_1","volume-title":"Attention-Guided Digital Adversarial Patches on Visual Detection. Security and Communication Networks 2021","author":"Lang Dapeng","year":"2021","unstructured":"Dapeng Lang , Deyun Chen , Ran Shi , and Yongjun He. 2021. Attention-Guided Digital Adversarial Patches on Visual Detection. Security and Communication Networks 2021 ( 2021 ). Dapeng Lang, Deyun Chen, Ran Shi, and Yongjun He. 2021. Attention-Guided Digital Adversarial Patches on Visual Detection. Security and Communication Networks 2021 (2021)."},{"key":"e_1_3_2_2_18_1","volume-title":"Seong Tae Kim, and Yong Man Ro.","author":"Lee Hakmin","year":"2020","unstructured":"Hakmin Lee , Hong Joo Lee , Seong Tae Kim, and Yong Man Ro. 2020 . Robust ensemble model training via random layer sampling against adversarial attack. arXiv preprint arXiv:2005.10757 (2020). Hakmin Lee, Hong Joo Lee, Seong Tae Kim, and Yong Man Ro. 2020. Robust ensemble model training via random layer sampling against adversarial attack. arXiv preprint arXiv:2005.10757 (2020)."},{"key":"e_1_3_2_2_19_1","volume-title":"On physical adversarial patches for object detection. arXiv preprint arXiv:1906.11897","author":"Lee Mark","year":"2019","unstructured":"Mark Lee and Zico Kolter . 2019. On physical adversarial patches for object detection. arXiv preprint arXiv:1906.11897 ( 2019 ). Mark Lee and Zico Kolter. 2019. On physical adversarial patches for object detection. arXiv preprint arXiv:1906.11897 (2019)."},{"key":"e_1_3_2_2_20_1","volume-title":"Exploring the vulnerability of single shot module in object detectors via imperceptible background patches. arXiv preprint arXiv:1809.05966","author":"Li Yuezun","year":"2018","unstructured":"Yuezun Li , Xiao Bian , Ming-Ching Chang , and Siwei Lyu . 2018. Exploring the vulnerability of single shot module in object detectors via imperceptible background patches. arXiv preprint arXiv:1809.05966 ( 2018 ). Yuezun Li, Xiao Bian, Ming-Ching Chang, and Siwei Lyu. 2018. Exploring the vulnerability of single shot module in object detectors via imperceptible background patches. arXiv preprint arXiv:1809.05966 (2018)."},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"e_1_3_2_2_22_1","volume-title":"Rama Chellappa, and Soheil Feizi.","author":"Liu Jiang","year":"2021","unstructured":"Jiang Liu , Alexander Levine , Chun Pong Lau , Rama Chellappa, and Soheil Feizi. 2021 . Segment and Complete: Defending Object Detectors against Adversarial Patch Attacks with Robust Patch Detection . arXiv preprint arXiv:2112.04532 (2021). Jiang Liu, Alexander Levine, Chun Pong Lau, Rama Chellappa, and Soheil Feizi. 2021. Segment and Complete: Defending Object Detectors against Adversarial Patch Attacks with Robust Patch Detection. arXiv preprint arXiv:2112.04532 (2021)."},{"key":"e_1_3_2_2_23_1","volume-title":"Dpatch: An adversarial patch attack on object detectors. arXiv preprint arXiv:1806.02299","author":"Liu Xin","year":"2018","unstructured":"Xin Liu , Huanrui Yang , Ziwei Liu , Linghao Song , Hai Li , and Yiran Chen . 2018 . Dpatch: An adversarial patch attack on object detectors. arXiv preprint arXiv:1806.02299 (2018). Xin Liu, Huanrui Yang, Ziwei Liu, Linghao Song, Hai Li, and Yiran Chen. 2018. Dpatch: An adversarial patch attack on object detectors. arXiv preprint arXiv:1806.02299 (2018)."},{"key":"e_1_3_2_2_24_1","volume-title":"Learning Transferable 3D Adversarial Cloaks for Deep Trained Detectors. arXiv preprint arXiv:2104.11101","author":"Maesumi Arman","year":"2021","unstructured":"Arman Maesumi , Mingkang Zhu , YiWang, Tianlong Chen , Zhangyang Wang , and Chandrajit Bajaj . 2021. Learning Transferable 3D Adversarial Cloaks for Deep Trained Detectors. arXiv preprint arXiv:2104.11101 ( 2021 ). Arman Maesumi, Mingkang Zhu, YiWang, Tianlong Chen, Zhangyang Wang, and Chandrajit Bajaj. 2021. Learning Transferable 3D Adversarial Cloaks for Deep Trained Detectors. arXiv preprint arXiv:2104.11101 (2021)."},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-61638-0_31"},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2019.00143"},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00507"},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3076225"},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-68238-5_32"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.690"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24574-4_28"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00400"},{"key":"e_1_3_2_2_33_1","volume-title":"12th USENIX workshop on offensive technologies (WOOT 18)","author":"Song Dawn","year":"2018","unstructured":"Dawn Song , Kevin Eykholt , Ivan Evtimov , Earlence Fernandes , Bo Li , Amir Rahmati , Florian Tramer , Atul Prakash , and Tadayoshi Kohno . 2018 . Physical adversarial examples for object detectors . In 12th USENIX workshop on offensive technologies (WOOT 18) . Dawn Song, Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li, Amir Rahmati, Florian Tramer, Atul Prakash, and Tadayoshi Kohno. 2018. Physical adversarial examples for object detectors. In 12th USENIX workshop on offensive technologies (WOOT 18)."},{"key":"e_1_3_2_2_34_1","volume-title":"Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199","author":"Szegedy Christian","year":"2013","unstructured":"Christian Szegedy , Wojciech Zaremba , Ilya Sutskever , Joan Bruna , Dumitru Erhan , Ian Goodfellow , and Rob Fergus . 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 ( 2013 ). Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)."},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475653"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2020.08.087"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"crossref","first-page":"508","DOI":"10.1109\/TCSVT.2014.2358031","article-title":"Efficient feature selection and classification for vehicle detection","volume":"25","author":"Wen Xuezhi","year":"2014","unstructured":"Xuezhi Wen , Ling Shao , Wei Fang , and Yu Xue . 2014 . Efficient feature selection and classification for vehicle detection . IEEE Transactions on Circuits and Systems for Video Technology 25 , 3 (2014), 508 -- 517 . Xuezhi Wen, Ling Shao, Wei Fang, and Yu Xue. 2014. Efficient feature selection and classification for vehicle detection. IEEE Transactions on Circuits and Systems for Video Technology 25, 3 (2014), 508--517.","journal-title":"IEEE Transactions on Circuits and Systems for Video Technology"},{"key":"e_1_3_2_2_39_1","first-page":"495","article-title":"Introduction to convolutional neural networks. National Key Lab for Novel Software Technology","volume":"5","author":"Wu Jianxin","year":"2017","unstructured":"Jianxin Wu . 2017 . Introduction to convolutional neural networks. National Key Lab for Novel Software Technology . Nanjing University. China 5 , 23 (2017), 495 . Jianxin Wu. 2017. Introduction to convolutional neural networks. National Key Lab for Novel Software Technology. Nanjing University. China 5, 23 (2017), 495.","journal-title":"Nanjing University. China"},{"key":"e_1_3_2_2_40_1","volume-title":"Defending against physically realizable attacks on image classification. arXiv preprint arXiv:1909.09552","author":"Wu Tong","year":"2019","unstructured":"Tong Wu , Liang Tong , and Yevgeniy Vorobeychik . 2019. Defending against physically realizable attacks on image classification. arXiv preprint arXiv:1909.09552 ( 2019 ). Tong Wu, Liang Tong, and Yevgeniy Vorobeychik. 2019. Defending against physically realizable attacks on image classification. arXiv preprint arXiv:1909.09552 (2019)."},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58548-8_1"},{"key":"e_1_3_2_2_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484757"},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58558-7_39"},{"key":"e_1_3_2_2_44_1","volume-title":"Hakmin Lee, and Yong Man Ro.","author":"Yu Youngjoon","year":"2022","unstructured":"Youngjoon Yu , Hong Joo Lee , Hakmin Lee, and Yong Man Ro. 2022 . Defending Against Person Hiding Adversarial Patch Attack with a Universal White Frame . arXiv preprint arXiv:2204.13004 (2022). Youngjoon Yu, Hong Joo Lee, Hakmin Lee, and Yong Man Ro. 2022. Defending Against Person Hiding Adversarial Patch Attack with a Universal White Frame. arXiv preprint arXiv:2204.13004 (2022)."},{"key":"e_1_3_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01136"},{"key":"e_1_3_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354259"}],"event":{"name":"MM '22: The 30th ACM International Conference on Multimedia","location":"Lisboa Portugal","acronym":"MM '22","sponsor":["SIGMM ACM Special Interest Group on Multimedia"]},"container-title":["Proceedings of the 30th ACM International Conference on Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3503161.3548362","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3503161.3548362","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:00:44Z","timestamp":1750186844000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3503161.3548362"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10,10]]},"references-count":46,"alternative-id":["10.1145\/3503161.3548362","10.1145\/3503161"],"URL":"https:\/\/doi.org\/10.1145\/3503161.3548362","relation":{},"subject":[],"published":{"date-parts":[[2022,10,10]]},"assertion":[{"value":"2022-10-10","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}